CVE-2015-2008: Medium severity ibm qradar security information and event manager vulnerability
Published Feb 15, 2016
·Updated
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.
Affected Software
7 affected components
IBM QRadar Security Information and Event Manager=7.1.0
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
Event History
Feb 15, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2008?
CVE-2015-2008 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-2008?
To fix CVE-2015-2008, update IBM QRadar SIEM to versions 7.1 MR2 Patch 12 or 7.2.6 and later.
3
What type of vulnerability is CVE-2015-2008?
CVE-2015-2008 is an information disclosure vulnerability that affects SSH private keys.
4
Who is affected by CVE-2015-2008?
Administrators of IBM QRadar SIEM versions prior to the specified patches are affected by CVE-2015-2008.
5
What information can be exposed due to CVE-2015-2008?
CVE-2015-2008 can expose sensitive SSH private keys contained in backup archives.